Attackers keep flinging assorted ImageMagick 0day exploits

It’s been a week since the existence of several flaws affecting popular image processing library ImageMagick have been made public. At the time, one of these, a remote code execution vulnerability (CVE-2016–3714) that is easy to trigger was already exploited in attacks in the wild. The bug has been patched in ImageMagick versions 7.0.1-2 and 6.9.4-0 that were pushed out on Friday, but according to Sucuri Security and CloudFlare, attackers still hope not all web … More Continue reading Attackers keep flinging assorted ImageMagick 0day exploits

WordPress Patches SOME, XSS Flaws in Version 4.5.2

WordPress has issued a security release, patching a SOME vulnerability in Plupload, and a reflected cross-site scripting bug in MediaElement.js. Continue reading WordPress Patches SOME, XSS Flaws in Version 4.5.2

Serious ImageMagick Zero-Day Vulnerabilities – ImageTragick?

So another vulnerability with a name and a logo – ImageTragick? At least this time it’s pretty dangerous, a bunch of ImageMagick Zero-Day vulnerabilities have been announced including one that can leave you susceptible to remote code execution. It’s pretty widely used software too and very public, if you use an app online that lets […]

The…

Read the full post at darknet.org.uk

Continue reading Serious ImageMagick Zero-Day Vulnerabilities – ImageTragick?